Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CL-STA-1087

Also known as: tracked as, UNC6619

Description

CL‑STA‑1087 is widely believed to be a Chinese state‑sponsored advanced persistent threat that has been active since 2020. The campaign’s primary objective is espionage against defense, government, media, critical infrastructure, mining, financial services, telecommunications, utilities, energy, and aviation sectors in countries such as China, the United States, Brazil, India, Mexico, Germany, Vietnam, Taiwan, Belarus, Poland, Italy, South Korea, Saudi Arabia, Japan, and Nigeria. Operationally the actors demonstrate exceptional patience: once an intruder foothold is established they often remain dormant for months or years, leveraging legitimate cloud services as their C2 infrastructure to blend with normal traffic and evade detection. Their toolset is broad and includes known commercial tools such as PowerShell and Cobalt Strike variants, open‑source reconnaissance utilities (e.g., TruffleHog), specialized custom backdoors, and a range of credential harvesting techniques (Mimikatz and OAuth token theft). They have also been observed manipulating file extensions, icons, and embedded images or scripts to masquerade malicious executables as benign office documents. The group leverages social engineering (spearphishing emails with malicious attachments or links) in combination with purchased intelligence to create highly targeted lures that improve the likelihood of user execution.

Goals & Targeting

Targeted Sectors

Defense
Government
Media
Critical infrastructure
Mining
Financial services
Telecommunications
Utilities
Energy
Aviation

Targeted Countries / Regions

CN
US
BR
IN
MX
DE
VN
TW
BY
PL
IT
KR
SA
JP
NG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

CL‑STA‑1087 is a state‑sponsored espionage group originating from China that has operated since at least 2020, primarily targeting military and critical infrastructure entities in Southeast Asia. The gang employs sophisticated spearphishing campaigns with malicious attachments or links designed to exploit software vulnerabilities, gather credentials—including OAuth tokens—and establish persistent, often dormant, cloud‑based command‑and‑control channels. Recent evidence shows a continued focus on precision intelligence collection while maintaining strong operational security, making detection and attribution challenging for defenders.

Goals & Targeting

CL‑STA‑1087’s strategic objective is long‑term state‑level espionage focused on acquiring tactical and operational intelligence from military and critical‑infrastructure targets. By embedding dormant access and using cloud native C2, the group can persist undetected while collecting data such as system inventories, network configurations, credentials, and documents. The use of spearphishing tailored to specific organizations suggests a goal to gain footholds inside sensitive networks for targeted information gathering rather than opportunistic sabotage.

Enhanced Description

Key Capabilities

  • Spearfishing with malicious attachments or links
  • Social engineering to harvest credentials and actionable intel
  • File extension and icon manipulation to disguise executables
  • Exploiting application vulnerabilities upon attachment opening
  • Embedding images or scripts in emails to exploit browsers or readers (web bugs)
  • Using cloud services for command‑and‑control
  • Maintaining dormant persistence within compromised environments
  • Harvesting OAuth access tokens
  • Compromising domain accounts, email accounts and code‑signing certificates
  • Conducting DNS reconnaissance and using CDNs
  • Performing AS-REP roasting for Kerberos credentials
  • Exploiting Windows Management Instrumentation (WMI) for execution
  • Disabling crypto hardware to evade detection
  • Using custom backdoors and remote access tools
  • Deploying rootkits and malicious DLLs

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: T1213
  2. unit42.paloaltonetworks.com — Cited by web research for: PowerShell
  3. unit42.paloaltonetworks.com — Cited by web research for: Web Shells
  4. thelaymansecurity.com — Cited by web research for: GoogleUpdate.exe

Intel Summary

40

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
China-based
military-targeting
cloud-based

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.